<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector - LDAPS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/212112#M40249</link>
    <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;sorry for the noise. DCs local firewalls refuse to answer to RPC when freshly deployed. Problem solved from my side.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 17:42:54 GMT</pubDate>
    <dc:creator>Jöran_Kaußel</dc:creator>
    <dc:date>2024-04-23T17:42:54Z</dc:date>
    <item>
      <title>Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70634#M11856</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When checking SK108235 for ports.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Communication Protocols&lt;/P&gt;&lt;TABLE border="1" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Direction&lt;/TD&gt;&lt;TD&gt;Port&lt;/TD&gt;&lt;TD&gt;Protocol&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Identity Collector to Identity Awareness Gateway&lt;/TD&gt;&lt;TD&gt;443&lt;/TD&gt;&lt;TD&gt;Proprietary Check Point protocol, over HTTPS.&lt;BR /&gt;Used for ongoing communication between the Agent and the Security Gateway.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Identity Awareness Gateway to Domain Controller&lt;/TD&gt;&lt;TD&gt;389 / 636&lt;/TD&gt;&lt;TD&gt;LDAP / LDAPS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Identity Collector to Domain Controller&lt;/TD&gt;&lt;TD&gt;53&lt;/TD&gt;&lt;TD&gt;DNS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;*Identity Collector to Domain Controller&lt;/TD&gt;&lt;TD&gt;389&lt;/TD&gt;&lt;TD&gt;LDAP&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Identity Collector to Domain Controller&lt;/TD&gt;&lt;TD&gt;135,&lt;BR /&gt;and dynamically&lt;BR /&gt;allocated ports&lt;/TD&gt;&lt;TD&gt;DCOM protocol, which makes extensive use of DCE/RPC.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Identity Collector to Cisco ISE&lt;/TD&gt;&lt;TD&gt;5222&lt;/TD&gt;&lt;TD&gt;Session subscribe. Gets notifications of new login/logout events.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Identity Collector to Cisco ISE&lt;/TD&gt;&lt;TD&gt;8910&lt;/TD&gt;&lt;TD&gt;Bulk session download. Fetches all the active sessions from the ISE Server.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;STRONG&gt;* Note:&lt;/STRONG&gt;&amp;nbsp;LDAPS is also optional (through port 636) when using "NetIQ eDirectory". For all other uses (which are the most common ones), we are using LDAP only.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I dont see LDAPS, 636 for standard Microsoft AD. not sure what this&amp;nbsp;NetIQ eDirectory is.&lt;BR /&gt;When is LDAPS 636 comming for IA if its not already present, (if so i dont see where to change it in the GUI)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Magnus&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 10:14:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70634#M11856</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2019-12-17T10:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70735#M11857</link>
      <description>I believe it's configured on the relevant LDAP Account Unit object.</description>
      <pubDate>Tue, 17 Dec 2019 20:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70735#M11857</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-17T20:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70740#M11858</link>
      <description>&lt;P&gt;Within smartconsole, yes sure.&lt;BR /&gt;But the Identity collector you dont have any options like that.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;And Microsoft is pushing pretty hard to remove LDAP for LDAPS,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="domain_ic.jpg" style="width: 455px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3785i775A78D91C44B1C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="domain_ic.jpg" alt="domain_ic.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ad_server.jpg" style="width: 415px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3786iBD92AB07EFDB7031/image-size/large?v=v2&amp;amp;px=999" role="button" title="ad_server.jpg" alt="ad_server.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 20:39:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70740#M11858</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2019-12-17T20:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70741#M11859</link>
      <description>&lt;P&gt;I'm guessing Identity Collector will try both LDAP and LDAPS but maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;can confirm.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 22:00:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70741#M11859</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-17T22:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70756#M11860</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Magnus,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;LDAP is used on Identity Collector in 2 ways:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;AD integration - only for discovering the AD servers in the environment. After this discovery, the entire communication is done securely&amp;nbsp;with Microsoft API. The discovery itself is performed with LDAP (not LDAPS).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;NetIQ eDirectory - this is an LDAP server by NetIQ, which we are communicating over LDAP / LDAPS all the way for fetching logged in users.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Royi Priov.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2019 07:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/70756#M11860</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2019-12-18T07:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/169754#M30768</link>
      <description>&lt;P&gt;Hi Royi&lt;/P&gt;&lt;P&gt;I have a customer that is exactly in the same situation, trying to move away from AD query and use Identity Collector... As the AD environment is configured to allow only LDAPS connections, the initial test connection to and AD server, using plain LDAP is unsuccessful and the&amp;nbsp; migration cannot progress further...&lt;/P&gt;&lt;P&gt;Is there any way of forcing the initial test connection to use LDAPS instead of LDAP? The customer has downloaded and installed the latest version of the Identity Collector software - R81.040.0000 / 20 Sep 2022...&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;Valeriu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 11:59:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/169754#M30768</guid>
      <dc:creator>Val1976</dc:creator>
      <dc:date>2023-01-31T11:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/170727#M30920</link>
      <description>&lt;P&gt;Hi Valeriu,&lt;/P&gt;&lt;P&gt;You can connect to the "Active Directory" LDAPS server if the LDAPS certificate contains the IP address of the DC in the SAN field.&lt;/P&gt;&lt;P&gt;Click New Source &amp;gt; Active Directory &amp;gt; Fetch Automatically and choose LDAP over SSL.&lt;/P&gt;&lt;P&gt;The IC only accepts IP address and the DC IP address must be entered.&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Zolo&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 13:32:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/170727#M30920</guid>
      <dc:creator>Zolo</dc:creator>
      <dc:date>2023-02-08T13:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211718#M40154</link>
      <description>&lt;P&gt;Hello Check Mates,&lt;/P&gt;&lt;P&gt;any tipps for those whose PKI does not support IPs in SAN field?&lt;/P&gt;&lt;P&gt;Any help appreciated,&lt;BR /&gt;Jöran&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 11:27:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211718#M40154</guid>
      <dc:creator>Jöran_Kaußel</dc:creator>
      <dc:date>2024-04-18T11:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211784#M40160</link>
      <description>&lt;P&gt;Upgrade to R82 when it's available as the validation mechanism for the LDAPS certificate will change.&lt;BR /&gt;Instead of validating the existing certificate, we'll ensure the certificate is valid and signed by a specific CA.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 19:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211784#M40160</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-18T19:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211821#M40174</link>
      <description>&lt;P&gt;Hello Jöran,&lt;/P&gt;&lt;P&gt;Good news &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As I checked, the latest IC version (R81.069.0000) finally supports FQDN.&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Zoli&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 06:54:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211821#M40174</guid>
      <dc:creator>Zolo</dc:creator>
      <dc:date>2024-04-19T06:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211846#M40184</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello Zolo,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;unfortunately I can't confirm. Using R81.069.0000 throughout the currently running DC migration to Windows Server 2022 I can only fetch them via the remaining 2016 DCs, not directly. And then I can't get them connected neither via IP, nor hostname or FQDN.&lt;/P&gt;&lt;P&gt;Fetching via IP works instantly while hostname and fqdn needs about 30 secs.&lt;/P&gt;&lt;P&gt;Error states "Unable to connect; please check connectivity with server and server firewall configuration". I can see tcp/udp 389 but no 636. Nothings getting dropped, tried debug options via regedit but got not significant more info other than "ErrCode (1722)" which seems to be a dead end.&lt;/P&gt;&lt;P&gt;Any tipps appreciated&lt;BR /&gt;Jöran&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 10:30:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/211846#M40184</guid>
      <dc:creator>Jöran_Kaußel</dc:creator>
      <dc:date>2024-04-19T10:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - LDAPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/212112#M40249</link>
      <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;sorry for the noise. DCs local firewalls refuse to answer to RPC when freshly deployed. Problem solved from my side.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 17:42:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-LDAPS/m-p/212112#M40249</guid>
      <dc:creator>Jöran_Kaußel</dc:creator>
      <dc:date>2024-04-23T17:42:54Z</dc:date>
    </item>
  </channel>
</rss>

